CtrlK
BlogDocsLog inGet started
Tessl Logo

self-hosted-runner-abuse

Self-hosted runner abuse — non-ephemeral runner persistence, fork-PR job execution on self-hosted, runner-label targeting, secret/token theft from runner env, lateral movement from runner into internal network and cloud metadata services.

65

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/exploit/cicd/self-hosted-runner-abuse/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a highly actionable, well-organized offensive-security reference with executable commands, explicit authorization/safety checkpoints, and clear cross-references. The main gaps are minor prose that could be trimmed and the absence of bundle-file split for progressive disclosure.

DimensionReasoningScore

Conciseness

The body is dense with executable commands, YAML, and tables and largely assumes Claude's competence, but a few prose passages (the 'attacker dreams' intro, the 'Stop.' callout, decision-gate framing) add minor commentary that could be trimmed, keeping it just below the lean 5 anchor.

4 / 5

Actionability

Nearly every section provides copy-paste-ready bash and YAML with explicitly templated placeholders and concrete examples covering recon, persistence, exfil, and lateral movement; matches the fully-executable anchor.

5 / 5

Workflow Clarity

Sections follow a coherent recon-to-lateral-move progression and include explicit safety checkpoints (a 4-rule Decision gate, a 'Stop' callout mandating TTL and cleanup, 'print first 8 chars only'), so the destructive-cap cap does not apply; it is not a 5 because the structure is a reference catalog rather than a single linear validate->fix->retry workflow.

4 / 5

Progressive Disclosure

Content is well-sectioned with clearly signaled one-level-deep cross-skill references (poisoned-pipeline-execution, cicd-secrets-exfil) and a References list, but no bundle files exist and all technique content is inlined in one ~175-line file rather than split out, so it does not reach the appropriately-split 5 anchor.

4 / 5

Total

17

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, well-scoped, and distinctive, clearly conveying the skill's offensive-security capabilities around self-hosted runners. Its main weakness is the absence of an explicit 'Use when...' trigger clause, which caps completeness at 3 despite strong 'what' coverage.

Suggestions

Append an explicit 'Use when ...' clause listing concrete trigger phrases (e.g. 'Use when assessing self-hosted GitHub/GitLab runners for persistence, fork-PR RCE, or runner-to-IMDS lateral movement') to lift completeness.

Add a few more natural-language synonyms users might actually say (e.g. 'CI runner', 'build agent', 'IMDS', '169.254.169.254') to broaden trigger-term coverage.

Keep the concrete capability list but pair it with the trigger clause so both 'what' and 'when' are explicitly answered.

DimensionReasoningScore

Specificity

Lists five concrete, distinct abuse actions ('non-ephemeral runner persistence', 'fork-PR job execution on self-hosted', 'runner-label targeting', 'secret/token theft from runner env', 'lateral movement ... into internal network and cloud metadata services'), matching the comprehensive-coverage anchor; no gaps warranting a 4.

5 / 5

Completeness

The 'what' is clear and concrete (the enumerated abuse capabilities), but there is no explicit 'Use when...' trigger clause; per the rubric guideline a missing explicit trigger clause caps completeness at 3.

3 / 5

Trigger Term Quality

Includes natural, relevant terms ('self-hosted runner', 'persistence', 'fork-PR', 'secret/token theft', 'lateral movement', 'metadata services') with good synonym coverage, but the phrasing is jargon-heavy and omits some common lay variations, so it sits just below the comprehensive 5 anchor.

4 / 5

Distinctiveness Conflict Risk

Targets a clearly scoped niche (self-hosted runner abuse) with distinct triggers, making conflict with unrelated skills minimal; matches the clear-niche anchor.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.